First published: Mon Feb 15 2016(Updated: )
IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.6 includes SSH private keys during backup operations, which allows remote authenticated administrators to obtain sensitive information by reading a backup archive.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | =7.1.0 | |
IBM QRadar Security Information and Event Manager | =7.2.0 | |
IBM QRadar Security Information and Event Manager | =7.2.1 | |
IBM QRadar Security Information and Event Manager | =7.2.2 | |
IBM QRadar Security Information and Event Manager | =7.2.3 | |
IBM QRadar Security Information and Event Manager | =7.2.4 | |
IBM QRadar Security Information and Event Manager | =7.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2008 is classified as a medium severity vulnerability.
To fix CVE-2015-2008, update IBM QRadar SIEM to versions 7.1 MR2 Patch 12 or 7.2.6 and later.
CVE-2015-2008 is an information disclosure vulnerability that affects SSH private keys.
Administrators of IBM QRadar SIEM versions prior to the specified patches are affected by CVE-2015-2008.
CVE-2015-2008 can expose sensitive SSH private keys contained in backup archives.